In July 2026, the European Union Agency for Cybersecurity (ENISA) published its market analysis: Cybersecurity Assessments: Certification Uptake & State of Play 2021–2025 (Version 1.1).
The report provides the first official multi-year dataset on how cybersecurity evaluation schemes are evolving across Europe. For manufacturers subject to the EU Cyber Resilience Act (CRA), the report highlights four major developments:
- The retirement of the 20-year SOG-IS agreement in February 2026.
- The operational deployment of the European Common Criteria scheme (EUCC).
- The European standardisation of fixed-time testing for SMEs under EN 17640 (FiTCEM).
- The expansion of EU certification mandates into Managed Security Services and Incident Response under Regulation (EU) 2025/37.
PortaRegulus published a detailed regulatory analysis of the numbers in its briefing: SOG-IS is dead, EUCC is live, and the SME middle is finally codified. Below is a summary of the operational takeaways for product teams.
1. SOG-IS Has Ended: EUCC Is the Mandatory EU Path
For more than twenty years, high-assurance Common Criteria evaluations in Europe operated under the SOG-IS Mutual Recognition Agreement. Seven historical certification bodies (France, Germany, Italy, Netherlands, Poland, Spain, and Sweden) issued certificates recognised across participant states.
As of February 2026, certification bodies cannot deliver SOG-IS certificates anymore.
All new Common Criteria certificates must now be issued under the European Cybersecurity Certification Scheme (EUCC). The ENISA report records the initial operational baseline:
- 17 EUCC certificates were issued during the 2025 transition period, with 20 additional certificates published in early 2026.
- 24 ITSEF testing laboratories are already accredited to conduct EUCC evaluations.
- 14 Certification Bodies are authorised across the European Union to issue EUCC certificates.
- 53% of worldwide Common Criteria laboratories (48 out of 91) are based in the European Union.
If your product requires third-party certification at "substantial" or "high" assurance levels—such as hardware secure elements or critical components under CRA Article 24—your evaluation laboratory must be accredited under EUCC.
2. EN 17640 (FiTCEM): Realistic Testing for SMEs
Traditional Common Criteria evaluations require extensive documentation and can cost upwards of €150,000 to €300,000 per product. This model is not practical for small and medium-sized enterprises (SMEs) building commercial IoT devices or industrial hardware.
To address this gap, European standardisation bodies CEN and CENELEC developed EN 17640 (FiTCEM: Fixed-Time Cybersecurity Evaluation Methodology for ICT Products).
FiTCEM formalises national fast-track schemes (such as French CSPN, German BSZ, Spanish LINCE, and Dutch BSPA). Instead of open-ended documentation audits, FiTCEM fixes the evaluation duration beforehand (typically 25 to 35 person-days) and focuses directly on vulnerability analysis and penetration testing.
The ENISA report highlights steady adoption:
- Germany's BSZ scheme integrated EN 17640 as its baseline methodology in version 2.0 (November 2023), issuing 14 certificates in 2025.
- France's CSPN formally declared conformity to FiTCEM, processing over 40 evaluations annually and delivering 17 certificates in 2025.
- Spain's LINCE reached 16 certificates in 2025 and is completing its formal mapping to EN 17640.
For manufacturers assessing products under CRA Module A (Internal Production Control) or Module B (EU-Type Examination), EN 17640 provides an affordable, repeatable testing framework that satisfies market surveillance authorities.
3. The 30x Surge in Consumer IoT Security Labels
Total assessments across ICT products grew to 1,928 in 2025, up from 1,155 in 2024.
This increase was driven primarily by consumer IoT labels:
- Germany BSI IT Security Label: Surged from 19 labels in 2024 to 567 labels in 2025.
- Singapore CLS: Issued 268 labels in 2025, operating under mutual recognition with Germany.
- SESIP (EN 17927): Standardised by CEN/CENELEC as EN 17927, climbing to 27 certified products in 2025.
- Legacy Private Schemes: Schemes without regulatory backing declined sharply. The ioXt Alliance dropped from 196 certificates in 2021 to 2 in 2025, as vendors shifted resources toward statutory mechanisms such as the US Cyber Trust Mark and EU CRA.
The surge in German BSI labels illustrates how manufacturers are using self-assessment baselines to prepare their technical documentation ahead of mandatory CRA enforcement.
4. Regulation (EU) 2025/37 and Incident Response Schemes
The report introduces Managed Security Services (MSS) following the adoption of Regulation (EU) 2025/37 (the targeted amendment to the EU Cybersecurity Act).
ENISA has launched an Ad Hoc Working Group to draft candidate European certification schemes for MSS providers, with the primary initial focus placed on Incident Response.
National schemes show rapid growth in this domain:
- Spain's ENS framework (CCN-STIC 896 for MSS) expanded to 3,186 certified companies in 2025.
- Germany (BSI Vorfallbearbeitung) and France (PRIS / PDIS / PAMS) maintain active qualification registries for incident detection, penetration testing, and incident response providers.
This framework directly supports CRA Article 14. From 11 September 2026, manufacturers must submit early-warning reports within 24 hours of becoming aware of an actively exploited vulnerability. Having qualified incident response processes in place is necessary to meet these deadlines.
Practical Steps for Manufacturers
To align your compliance programme with the new European certification ecosystem:
- Verify Laboratory Accreditations: If your product requires Common Criteria certification, ensure your testing partner is accredited under EUCC rather than legacy SOG-IS arrangements.
- Adopt EN 17640 for Hardware Testing: Use fixed-time evaluations to validate your vulnerability handling and penetration testing without prohibitive evaluation costs.
- Automate Technical Documentation: Structure your CRA Annex VII technical file, SBOMs, and risk assessments into a single verifiable compliance workspace.
- Establish Coordinated Vulnerability Disclosure: Set up your RFC 9116 security.txt and disclosure portal before Article 14 mandatory reporting takes effect on 11 September 2026.
You can set up your free coordinated vulnerability disclosure portal on CVD Portal and test your readiness using our free CRA Maturity Assessment.